CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.

The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.

Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.

I assume it is this CISA: https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency

  • Zwuzelmaus@feddit.org
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 day ago

    disconnect […] from the internet

    And these guys really think that this is doable as easy as snapping your fingers?

    hmm…

    And these guys really are national advisors on things related to computers and internet??

    hmmmmm…

    • Godort@lemmy.ca
      link
      fedilink
      English
      arrow-up
      20
      ·
      1 day ago

      The specific advice they give is to disconnect all PLCs and only access them through a VPN, enable password protection and change the default passwords, and only allow IPs from known engineering laptops and other critical assets.

      This is absolutely doable and any IT professional could manage this change. The only barrier that prevented this from happening before is that you need buy-in from someone with access to the purse strings